Amazines Free Article Archive
www.amazines.com - Tuesday, May 21, 2024
Read about the most recent changes and happenings at Amazines.com
Log into your account or register as a new author. Start submitting your articles right now!
Search our database for articles.
Subscribe to receive articles emailed straight to your email account. You may choose multiple categories.
View our newest articles submitted by our authors.
View our most top rated articles rated by our visitors.
* Please note that this is NOT the ARTICLE manager
Add a new EZINE, or manage your EZINE submission.
Add fresh, free web content to your site such as newest articles, web tools, and quotes with a single piece of code!
Home What's New? Submit/Manage Articles Latest Posts Top Rated Article Search
Google
Subscriptions Manage Ezines
CATEGORIES
 Article Archive
 Advertising (133573)
 Advice (161671)
 Affiliate Programs (34799)
 Art and Culture (73857)
 Automotive (145712)
 Blogs (75615)
 Boating (9851)
 Books (17223)
 Buddhism (4130)
 Business (1330670)
 Business News (426453)
 Business Opportunities (366518)
 Camping (10973)
 Career (72795)
 Christianity (15848)
 Collecting (11638)
 Communication (115089)
 Computers (241955)
 Construction (38962)
 Consumer (49953)
 Cooking (17080)
 Copywriting (6733)
 Crafts (18203)
 Cuisine (7549)
 Current Affairs (20320)
 Dating (45907)
 EBooks (19703)
 E-Commerce (48258)
 Education (185525)
 Electronics (83524)
 Email (6438)
 Entertainment (159857)
 Environment (28973)
 Ezine (3040)
 Ezine Publishing (5454)
 Ezine Sites (1551)
 Family & Parenting (111009)
 Fashion & Cosmetics (196608)
 Female Entrepreneurs (11853)
 Feng Shui (134)
 Finance & Investment (310616)
 Fitness (106469)
 Food & Beverages (63046)
 Free Web Resources (7941)
 Gambling (30227)
 Gardening (25202)
 Government (10519)
 Health (630142)
 Hinduism (2206)
 Hobbies (44083)
 Home Business (91672)
 Home Improvement (251219)
 Home Repair (46246)
 Humor (4724)
 Import - Export (5459)
 Insurance (45104)
 Interior Design (29616)
 International Property (3488)
 Internet (191032)
 Internet Marketing (146687)
 Investment (22861)
 Islam (1161)
 Judaism (1352)
 Law (80507)
 Link Popularity (4596)
 Manufacturing (20914)
 Marketing (99319)
 MLM (14140)
 Motivation (18233)
 Music (27000)
 New to the Internet (9496)
 Non-Profit Organizations (4048)
 Online Shopping (129734)
 Organizing (7813)
 Party Ideas (11855)
 Pets (38165)
 Poetry (2229)
 Press Release (12689)
 Public Speaking (5643)
 Publishing (7566)
 Quotes (2407)
 Real Estate (126719)
 Recreation & Leisure (95495)
 Relationships (87674)
 Research (16182)
 Sales (80351)
 Science & Technology (110295)
 Search Engines (23514)
 Self Improvement (153300)
 Seniors (6220)
 Sexuality (36010)
 Small Business (49312)
 Software (83036)
 Spiritual (23517)
 Sports (116155)
 Tax (7663)
 Telecommuting (34070)
 Travel & Tourism (308307)
 UK Property Investment (3123)
 Video Games (13382)
 Web Traffic (11791)
 Website Design (56920)
 Website Promotion (36664)
 World News (1000+)
 Writing (35843)
Author Spotlight
CURTIS ENGLAND

I'm a full-time Writer, dreamer and chief executive manager. I write to release my true stories in t...more
ROBERT HOWARD

The Word of God is as, “Sweet as Honey”. God has Taken Me Through a Whole Lot of Things...more
MARTIN ADAM

Working in this organization from last 10 years. I did my graduation from the University of Texas, U...more
DESIGNPLUZ DIGITALAGENCY

Designpluz has steadily matured from a passionate graphics design start-up, into a full service digi...more
ELLIOT CHANG

Financial analyst and author writing on economy and business. ...more


Kenneth van wyk: what users can do to make their smartphones moresecure - China Vibrating Screener by guo ping





Article Author Biography
Kenneth van wyk: what users can do to make their smartphones moresecure - China Vibrating Screener by
Article Posted: 03/02/2013
Article Views: 38
Articles Written: 1013
Word Count: 1087
Article Votes: 0
AddThis Social Bookmark Button

Kenneth van wyk: what users can do to make their smartphones moresecure - China Vibrating Screener


 
Business,Business News,Business Opportunities
The sky is falling! The sky is falling! A lot of Chicken Littles are running around warning about the endof the world, brought about by the insecurity of mobile devices.There's a kernel of truth there, and I myself have bemoaned the state of mobile security . But there's also a good deal of exaggeration, born of (oftenvendor-fanned) fear, uncertainty and doubt. So, what's a user todo? Let's explore that a bit. Broadly speaking, you have three choices: Avoid mobile devicesaltogether, carefully select the apps you install and use, or diveright in and hope for the best.

The one sure bet is to avoid smartphones and other modern mobile devices, but that doesn't sound like a lotof fun to me. There are a lot of really useful and ingenious appsout there, so you'd be robbing yourself of some greatopportunities. Nonetheless, using a dumb phone may well be areasonable course of action for some people. If all you seek fromyour mobile phone is the ability to send and receive voice calls,and perhaps an occasional text message, then you should find noshortage of free, carrier-subsidized dumb phones.

You would indeedhave fewer security worries, and more money in your pocket. I just don't think that option is going to appeal to a lot ofpeople. At the other extreme, diving in without regard for safetyseems reckless. If you are hell-bent on maximizing the convenienceof your smartphone, you'll be tempted by apps that help you manageyour money, make payments, receive payments, transfer funds -- thelist just keeps going. But what sort of person does that withoutthinking about the danger of exposing sensitive information on adevice that is easy to steal or lose? Personally, I've taken a middle road.

I do have a smartphone, butI'm careful about the apps I install. What does it mean to becareful? Since I'm in the security field myself, it means that Ivet the apps myself. But a lot of what I do can be done by justabout anyone who knows a little bit about applications. Here are acouple of things you can try. Static analysis.

Maybe you didn't realize it, but you can pokearound an app's sandbox and take a look at what's in there foryourself. All you need are your mobile device, a USB cable and freesoftware such as iExplorer that lets you look at the files in each app on your device. (Note:These examples are primarily for Apple 's iOS, but similar tools and methods can be used on Android as well.) Connect your device to your computer (Mac or Windows) and useiExplorer to peek into its files. In each app's ~/Documents folder,you'll find files used by the app. Some common file extensions are.plist, .db, .xml and .txt.

The first are "properties files," whichare in an XML format and can be viewed using any text editor. Next,db files are database files -- likely SQLite3 files that can beviewed using sqlite3 on the command line. The other files aremostly text files as well. Drag them onto your main computer'sdesktop (or folder) and look at them one at a time. Look, forexample, in the plist files for usernames, passwords and otherapplication credentials.

For SQLite files, try opening a commandshell and typing "sqlite3 [filename.db]". Next, at the sqliteprompt, type ".tables" and you'll see whatever tables are presentin the database. You can view those tables by typing ".dump[table_name]". Again, look for usernames, passwords, etc.

Look also in each app's ~/Library folder. In there, you'll find aCaches folder and a bunch of other stuff. Poke through there andlook at the files. Again, look for properties files and databasefiles, as well as image files. Depending on when you last ran theapp, you may find some .jpg or .png files containing screenshots ofyour last session.

View them all. What you're looking for are some fundamental mistakes thatdevelopers commonly make. Storing usernames and passwords inproperties files, database files, etc., is sloppy programming.(There are keychains that do a far better -- though not perfect --job at securing that sort of data.) If the app you're considering using makes such simple mistakes, youmight want to avoid it. You could contact the vendor and ask it tofix it. You could also write a review for the app store you use andlet other people know about the problems.

I have done both, becauseI'm not willing to let such easily avoided mistakes go byunchallenged. If enough people do this sort of thing, I'm convincedthat app security will improve. Dynamic analysis. This one is a bit trickier, though still nottough to do. Use a network proxy tool such as Burp Suite or OWASP's Zap on your main computer (Windows, Mac or Linux ).

Turn on the proxy on your active Ethernet connection. Next, configure your mobile device to point its network proxy tothe IP number of the computer running the proxy testing tool. Nowyou'll be intercepting all of your mobile device's network traffic,and you can look inside it. Some common mistakes to look for here are sending usernames,passwords, session tokens or hardware identifiers through a networkwithout encrypting them.

Believe it or not, this is not uncommon.Another mistake that many apps make is to trust self-signed SSLcertificates (which both Burp Suite and Zap can automaticallygenerate). By not properly verifying a server's SSL certificate,mobile apps open their users up to man-in-the-middle attacks. Thistoo is sadly not uncommon in today's apps. If you find any of these things, they should give you pause. Ofcourse, not finding any of these mistakes is no guarantee ofsafety, but that doesn't mean it's not worth exploring the apps youwant to use.

Oh, and if any of the apps you want to use do make any of thesecommon mistakes, think about pointing the developers to OWASP'siGoat (for iOS developers) or OWASP's GoatDroid (for Androiddevelopers). Both are free learning tools to help expose developersto common problems and their solutions. With more than 20 years in the information security field, Kennethvan Wyk has worked at Carnegie Mellon University's CERT/CC, theU.S. Deptartment of Defense, Para-Protect and others.

He haspublished two books on information security and is working on athird. He is the president and principal consultant at KRvWAssociates LLC in Alexandria, Va. Read more about security in Computerworld's Security Topic Center.

The e-commerce company in China offers quality products such as China Vibrating Screener , Pellet Mill Die, and more. For more , please visit Hammer Mill Machine today!

Related Articles - China Vibrating Screener, Pellet Mill Die,

Email this Article to a Friend!

Receive Articles like this one direct to your email box!
Subscribe for free today!

 Rate This Article  
Completely useless, should be removed from directory.
Minimal useful information.
Decent and informative.
Great article, very informative and helpful.
A 'Must Read'.

 

Do you Agree or Disagree? Have a Comment? POST IT!

 Reader Opinions 
Submit your comments and they will be posted here.
Make this comment or to the Author only:
Name:
Email:
*Your email will NOT be posted. This is for administrative purposes only.
Comments: *Your Comments WILL be posted to the AUTHOR ONLY if you select PRIVATE and to this PUBLIC PAGE if you select PUBLIC, so write accordingly.
 
Please enter the code in the image:



 Author Login 
LOGIN
Register for Author Account

 

Advertiser Login

 

ADVERTISE HERE NOW!
   Limited Time $60 Offer!
   90  Days-1.5 Million Views  

 

Great Paranormal Romance


GENE MYERS

Author of four books and two screenplays; frequent magazine contributor. I have four other books "in...more
TIM FAY

After 60-plus years of living, I am just trying to pass down some of the information that I have lea...more
LAURA JEEVES

At LeadGenerators, we specialise in content-led Online Marketing Strategies for our clients in the t...more
STEPHEN BYE

Steve Bye is currently a fiction writer, who published his first novel, ‘Looking Forward Through the...more
ALEX BELSEY

I am the editor of QUAY Magazine, a B2B publication based in the South West of the UK. I am also the...more
SUSAN FRIESEN

Located in the lower mainland of B.C., Susan Friesen is a visionary brand strategist, entrepreneur, ...more
STEVERT MCKENZIE

Stevert Mckenzie, Travel Enthusiast. ...more
SHALINI MITTAL

A postgraduate in Fashion Technology. Shalini is a writer at heart! Writing for her is an expression...more
ADRIAN JOELE

I have been involved in nutrition and weight management for over 12 years and I like to share my kn...more
JAMES KENNY

James is a Research Enthusiast that focuses on the understanding of how things work and can be impro...more

HomeLinksAbout UsContact UsTerms of UsePrivacy PolicyFAQResources
Copyright © 2024, All rights reserved.
Some pages may contain portions of text relating to certain topics obtained from wikipedia.org under the GNU FDL license